What is the PDPA?

What is the PDPA?

Thailand’s Personal Data Protection Act (PDPA) B.E. 2562 is the country’s primary data protection law that governs how organizations must collect, use, disclose, store, transfer, and safeguard personal data. The law aims to give individuals more control over their data while ensuring that businesses operate with transparency, accountability, and strong security measures.

To help organizations meet these obligations, ManageEngine offers a comprehensive suite of IT management and security solutions that strengthen data protection, enhance internal governance, and support PDPA compliance across the entire data life cycle. Our solutions enable you to enforce access controls, secure sensitive information, monitor data activities, automate compliance processes, and respond effectively to data subject requests.
Whether you are managing identities, securing endpoints, monitoring logs, handling incidents, or protecting sensitive assets, ManageEngine equips you with the tools required to build a secure, resilient, and PDPA-ready environment.

What is the PDPA?

The role of PDPA in IT

The PDPA directly shapes how organizations manage and protect personal data across IT
environments. It sets clear requirements for security controls, access management,
record-keeping, and transparency—compelling IT teams to build systems that are secure
by design and aligned with legal obligations.

  • Establishing data governance and accountability

    The PDPA requires organizations to define how personal data is collected, used, stored, and deleted.

    IT teams must implement:

    • Data classification.
    • Data retention policies.
    • Audit trails.
    • Secure system configurations.

    This ensures transparency and proper accountability.

  • Strengthening security controls and risk management

    An organization’s IT teams plays a central role in preventing data breaches for that organization.

    The PDPA requires:

    • Access control.
    • Encryption.
    • Monitoring and logging.
    • Incident response plans.
    • Secure data transfer.

    This pushes IT teams to proactively secure all systems that store or process personal data.

  • Enforcing access and identity management

    The PDPA mandates that only authorized personnel can access personal data.

    The IT team must enable:

    • Role-based access control (RBAC).
    • Privileged access management.
    • Identity verification.
    • Multi-factor authentication (MFA).

    This reduces risk from insider threats and unauthorized access.

  • Supporting data subject rights

    The law grants individuals rights such as access, rectification, portability, and deletion.

    IT systems must be capable of:

    • Retrieving personal data quickly.
    • Updating or correcting records.
    • Exporting data in readable formats.
    • Anonymizing or deleting data securely.

    These capabilities require proper system design and integration.

  • Ensuring secure cross-border data transfer

    If personal data is transferred abroad, IT teams must ensure:

    • Adequate protection measures.
    • Encryption in transit.
    • Compliance with approved transfer mechanisms.
  • Maintaining auditability and monitoring

    The PDPA requires organizations to show evidence of compliance.

    IT systems must:

    • Generate logs.
    • Track data access.
    • Detect anomalies.
    • Provide audit reports.

    This helps organizations respond to regulatory inquiries and assess internal risks.

  • Supporting the role of the Data Protection Officer (DPO)

    DPOs rely heavily on IT systems to:

    • Monitor compliance.
    • Review security measures.
    • Respond to incidents.
    • Assess vendor risks.
    • Maintain documentation.

    IT teams provide the technical foundation needed for DPO oversight.

How do ManageEngine solutions support
PDPA compliance?

  • Section 21
  • Section 22
  • Section 25
  • Section 26
  • Section 29
  • Section 30
  • Section 31
  • Section 32
  • Section 33
  • Section 34
  • Section 35
  • Section 36
  • Section 37
  • Section 40
  • Section 41–42
Section 21

Purpose limitation

Personal data must be used only for the purposes communicated to the data subject.

The ManageEngine product that can help you comply

  • Endpoint DLP Plus

    • Control personal data transfers to prevent unauthorized use.
    • Log sensitive data movement for review and auditing.
Section 22

Data minimization

Only the minimum necessary personal data may be collected or stored.

The ManageEngine product that can help you comply

  • DataSecurity Plus

    • Identify personal data stored across servers.
    • Highlight redundant or excessive data sets to support minimization.
Section 25

Indirect collection of personal data

If personal data is collected from sources other than the data subject, the controller must ensure transparency and lawful basis.

The ManageEngine product that can help you comply

  • DataSecurity Plus

    • Locate personal data stored across systems.
    • Help verify that indirectly collected data is used appropriately.
Section 26

Sensitive personal data

Sensitive personal data requires explicit consent and strong protection.

The ManageEngine products that can help you comply

  • Endpoint Central

    • Restrict user privileges on local machines, ensuring standard users cannot alter security controls or extract sensitive personal data without administrative approval.
    • Continuously scan for misconfigurations and high-risk software on endpoints that handle sensitive personal data, allowing IT teams to lock down vulnerable assets proactively.
  • Endpoint DLP Plus

    • Prevent unauthorized transfer or exposure of sensitive files.
    • Apply policies to ensure sensitive data remains protected.
  • PAM360

    • Control and monitor privileged access to systems containing sensitive data.
    • Record privileged activity for accountability and review.
  • Password Manager Pro

    • Protect privileged credentials used to access sensitive environments.
    • Maintain detailed logs of credential usage.
  • Log360

    • Monitor access to repositories containing sensitive personal data.
    • Detect unusual activities involving high-risk data.
Section 29

Corporate rules for data transfer (BCRs)

Organizations within the same group may transfer data internationally under an approved internal policy.

The ManageEngine products that can help you comply

  • Log360

    • Track data access and movement across systems.
    • Collect evidence that internal transfer policies are followed for audits.
  • DataSecurity Plus

    • Identify where personal data resides across the environment.
    • Support verification that data is handled according to internal rules.
Section 30

Right of access

Individuals may request access to their personal data.

The ManageEngine products that can help you comply

  • Log360

    • See audit trails showing how data was accessed.
    • Support verification of access history.
  • DataSecurity Plus

    • Locate personal data across file servers for retrieval.
    • Help prepare accurate datasets for access requests.
Section 31

Right to data portability

Individuals may request their personal data in a structured, machine-readable format.

The ManageEngine product that can help you comply

  • DataSecurity Plus

    • Identify all relevant personal data for export.
    • View reports to support data compilation.
Section 32

Right to object

Individuals may object to certain types of data processing.

The ManageEngine products that can help you comply

  • Log360

    • Confirm whether access to personal data has been halted.
    • Generate alerts if restricted data is accessed after an objection.
  • DataSecurity Plus

    • Identify files and locations tied to objection requests.
    • Help verify that processing has stopped.
Section 33

Right to erasure

Individuals may request deletion, destruction, or anonymization of personal data.

The ManageEngine products that can help you comply

  • Endpoint Central

    • Execute remote wipe and corporate wipe commands on lost, stolen, or retired devices to erase personal data permanently and prevent unauthorized recovery.
  • Log360

    • Track and audit data deletion activities in a database.
  • ADAudit Plus

    • Track file deletions by monitoring activities like file and folder creation, modification, and deletion.
  • DataSecurity Plus

    • Identify personal data for deletion.
    • Verify removal to prevent reappearance of redundant copies.
Section 34

Right to restrict processing

Processing of personal data must be temporarily halted when requested.

The ManageEngine product that can help you comply

  • Log360

    • Verify that no access occurs during a restriction period.
    • View audit logs to demonstrate compliance.
Section 35

Data accuracy

Organizations must ensure personal data is accurate and up to date.

The ManageEngine product that can help you comply

  • Log360

    • Verify that no access occurs during a restriction period.
    • View audit logs to demonstrate compliance.
Section 36

Record of correction requests

If a correction request is denied, the organization must record the request and the reason.

The ManageEngine product that can help you comply

  • Log360

    • Track access and changes to personal data.
    • View logs that support audits and regulatory reviews.
Section 37

Duties of a data controller

Organizations must implement security measures, access control, risk management, and incident response.

The ManageEngine products that can help you comply

  • Endpoint Central

    • Apply automated OS and third-party patches to remediate vulnerabilities before they can be exploited to breach personal data.
    • Enforce critical security configurations, such as BitLocker/FileVault encryption, ensuring personal data remains secure at rest even if a device is lost or stolen.
    • Implement device control policies to restrict unauthorized USBs and peripherals, preventing the physical exfiltration of sensitive data.
  • AD360

    • Back up and restore AD, Entra ID, and Microsoft 365 objects to recover personal data lost through unauthorized deletion or alteration.
    • Enforces MFA, conditional access, and SSO to ensure only verified users access systems holding Personal Data.
    • Run scheduled access reviews to revoke stale or excessive rights and uphold least-privilege.
    • Perform continuous risk assessments on user activity to surface anomalies and keep security measures aligned with evolving threats.
  • ADManager Plus

    • Manage user access rights to enforce least-privilege controls.
    • Help reduce unauthorized access risks.
  • Log360

    • Detect unusual activities involving personal data.
    • Get alerts and audit reports to support incident response.
  • ADAudit Plus

    • Track identity and directory changes affecting personal data.
    • Gain visibility into user activity across the environment.
  • DataSecurity Plus

    • Scan file servers to discover and classify personal data, and automate deletion, quarantine, or archival when retention periods expire or data is no longer needed.
Section 40

Duties of a data processor

Processors must follow the controller’s instructions and safeguard personal data.

The ManageEngine products that can help you comply

  • Endpoint Central

    • Implement strict configuration and policy controls (e.g., disabling unauthorized data-sharing protocols) as defined by the controller.
    • Utilize application control to block unauthorized or shadow IT software from running, ensuring only sanctioned apps can process personal data.
    • Ensure consistent enforcement across all managed endpoints (Windows, Mac, Linux, and mobile devices) through continuous compliance monitoring.
  • Log360

    • Record processor activities that involve personal data.
    • Gain transparency for audits and accountability.
  • AD360

    • Back up and restore AD, Entra ID, and Microsoft 365 objects to recover personal data lost through unauthorized or illegal deletion or alteration.
    • Enforce MFA, conditional access, and SSO to ensure only verified users access systems holding personal data.
    • Run scheduled access reviews to revoke stale or excessive rights and uphold least-privilege.
Section 41–42

Data protection officer (DPO)

Organizations must designate a DPO to oversee compliance and monitor processing activities.

The ManageEngine products that can help you comply

  • Log360

    • View detailed activity reports needed for DPO oversight.
    • Identify risks and monitor compliance continuously.
  • DataSecurity Plus

    • See where personal data is stored and how it is used.
    • Give the DPO visibility into data protection practices.

Get guidance on PDPA compliance

Talk to our experts to get more information on how your organization can comply with the PDPA.

Please enter the name

By clicking ‘Download now’, you agree to the processing of personal data according to our Privacy Policy.

Frequently Asked Questions

What is the Personal Data Protection Committee?

The Personal Data Protection Committee (PDPC) is the regulatory authority established under Thailand’s Personal Data Protection Act B.E. 2562. It operates through its secretariat office, the Office of the Personal Data Protection Committee (OPDPC).

The PDPC’s core responsibilities include:

Issuing guidelines: Setting standards, regulations, and best practices for personal data handling across industries.

Supervision and enforcement: Investigating and taking action against data controllers and processors that violate the law.

Handling complaints: Receiving and adjudicating complaints from data subjects whose rights have been infringed.

Advisory support: Providing guidance and resources to help organizations achieve compliance.

Why should businesses comply to the PDPA?

Thailand’s PDPA has been fully enforceable since June 1, 2022. It applies to any organization—Thai or foreign—that collects, uses, or discloses personal data of individuals in Thailand.

Who needs to be involved in PDPA compliance?

PDPA defines clear roles with distinct responsibilities for anyone who touches personal data:

Data controller: The person or organization that determines the purposes and means of collecting and using personal data. This is typically the company itself (e.g., an e-commerce platform storing customer data).

Data processor: A person or organization that processes data on behalf of and under the instructions of a data controller. Examples include cloud providers, HR outsourcing firms, and third-party analytics vendors.

Data protection officer (DPO): Certain organizations are required by law to appoint a DPO, particularly those that process sensitive personal data at scale or conduct large-scale systematic monitoring.

Who benefits from complying with the PDPA?

Data subjects (individuals): Customers and the public gain enforceable rights: the right to access, rectify, delete, restrict, and object to the use of their personal data.

Organizations (data controllers): Reduced legal liability, stronger customer relationships, and a more mature internal data governance culture.

Business partners and suppliers: Clear contractual frameworks for data sharing reduce ambiguity and disputes in B2B relationships.

Investors: Organizations with solid compliance postures present lower regulatory risk profiles, making them more attractive for investment.

Thailand’s digital economy: Broad adoption of PDPA principles builds systemic trust in digital services, accelerating adoption and growth.

What are the penalties for non-compliance with the PDPA?

The PDPA establishes three tiers of penalties:

Administrative fine: Up to THB 5,000,000.

Civil damages (punitive): Up to two times the cost of the actual damages.

Criminal imprisonment (up to one year): Criminal fine (combined) up to THB 1,000,000.

The most severe penalties apply to unauthorized collection of sensitive personal data and using personal data for personal gain or unauthorized disclosure to third parties. Directors and senior executives can be held personally liable if found to have consented to or been complicit in a violation.

Disclaimer:

The complete implementation of PDPA requires a combination of governance processes and policies, as well as people, technical and organizational measures. The features and capabilities described above represent some of the ways in which our solutions may support organizations in meeting certain PDPA requirements.


Organizations should conduct their own independent assessment of how these solutions align with their specific needs and help achieve compliance with this law.


This material is provided for informational purposes only and should not be construed as legal advice or a guarantee of compliance with the PDPA. ManageEngine makes no warranties, whether express, implied or statutory about the information in this material. Please consult your legal advisor to understand how PDPA applies to your organization and steps required to comply with its obligations.